Feeds

Italian police net 26 in phishing takedown

Phish, Chip and Mules

Beginner's guide to SSL certificates

Italian police have arrested 26 people allegedly involved in an international phishing operation.

The Guardia di Finanza (Military Financial Police) cuffed 18 Italian citizens and eight Eastern Europeans as part of "Phish and Chip", an operation aimed at dismantling a gang targeting users of Poste Italiane's home banking services.

The gang allegedly mounted a spamming campaign directing prospective marks towards overseas websites that mimicked the real Italian Post Office website. Victims were duped into handing over login credentials by bogus emails posing as security alerts.

Laptop computers, data backup kit, false documents, mobile phones, and equipment for creating credit cards were seized by police in the course of the raids that accompanied the arrests. Some of the seized items included Banca Intesa credit cards, said to have been used by the gang at the Casino of San Remo in the days leading up to their detention.

According to a police statement, an unnamed 22-year-old hacker was the linchpin of the scheme. Once account login credentials were obtained, lower ranked members of the gang (phishing mules) emptied funds from compromised accounts, transferring money to PostePay cards activated by members of the gang.

The alleged ringleader is protesting his innocence, maintaining during police questioning that he was one of the good guys - a data processing consultant who helped Italian companies prevent credit card fraud.

Security experts welcomed news of the arrests but warned against any complacency, noting that many cybercriminals remain at large. "Phishing and identity theft are global problems, and countries need to work more closely with each other to bring cybercriminals to justice, on illegal activity like this. Internet criminals can use technology to hide their identities, and it can often be a complex web for the police to untangle," said Graham Cluley, senior technology consultant for Sophos.

"These arrests underline the growing organised nature of international identity theft gangs, but there are many other phishers still at large."

Earlier this month, more than 10,000 web pages based in Italy were attacked by hackers who planted exploit code designed to open up compromised machines to identity theft. It's unclear at this stage whether or not any of the arrested gang were involved in this attack. ®

Protecting users from Firesheep and other Sidejacking attacks with SSL

More from The Register

next story
Spies would need SUPER POWERS to tap undersea cables
Why mess with armoured 10kV cables when land-based, and legal, snoop tools are easier?
Early result from Scots indyref vote? NAW, Jimmy - it's a SCAM
Anyone claiming to know before tomorrow is telling porkies
Apple Pay is a tidy payday for Apple with 0.15% cut, sources say
Cupertino slurps 15 cents from every $100 purchase
Israeli spies rebel over mass-snooping on innocent Palestinians
'Disciplinary treatment will be sharp and clear' vow spy-chiefs
YouTube, Amazon and Yahoo! caught in malvertising mess
Cisco says 'Kyle and Stan' attack is spreading through compromised ad networks
Hackers pop Brazil newspaper to root home routers
Step One: try default passwords. Step Two: Repeat Step One until success
China hacked US Army transport orgs TWENTY TIMES in ONE YEAR
FBI et al knew of nine hacks - but didn't tell TRANSCOM
Microsoft to patch ASP.NET mess even if you don't
We know what's good for you, because we made the mess says Redmond
NORKS ban Wi-Fi and satellite internet at embassies
Crackdown on tardy diplomatic sysadmins providing accidental unfiltered internet access
prev story

Whitepapers

Providing a secure and efficient Helpdesk
A single remote control platform for user support is be key to providing an efficient helpdesk. Retain full control over the way in which screen and keystroke data is transmitted.
WIN a very cool portable ZX Spectrum
Win a one-off portable Spectrum built by legendary hardware hacker Ben Heck
Saudi Petroleum chooses Tegile storage solution
A storage solution that addresses company growth and performance for business-critical applications of caseware archive and search along with other key operational systems.
Protecting users from Firesheep and other Sidejacking attacks with SSL
Discussing the vulnerabilities inherent in Wi-Fi networks, and how using TLS/SSL for your entire site will assure security.
Security for virtualized datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.